Revolut confirms customer data breach via fake government requests

Sensitive identity documents and transaction histories exposed in 'sophisticated external impersonation scam'

edit
By LineZotpaper
Published
Read Time2 min
British fintech Revolut has confirmed that an unauthorized third party obtained sensitive customer information by sending fraudulent requests from a legitimate government agency email domain. The exposed data includes names, contact details, copies of passports and driver's licenses, verification selfies, account statements, and transaction histories. Revolut said a limited number of customers were affected and that it has contacted them directly.

London-based fintech Revolut confirmed that it disclosed sensitive customer information to an unauthorized third party after receiving fraudulent requests sent from a legitimate government agency email domain.

The exposed data included customers' identity and contact details, including their birth date, postal and email addresses, and phone numbers, as well as copies of their identity documents including passports and driver's licenses, according to a notification emailed to affected customers and reviewed by TechCrunch. The data may have also included verification selfies, account statements, and transaction histories.

A Revolut spokesperson said the company identified a "sophisticated external impersonation scam" where an unauthorised third party used a legitimate government agency domain email to submit fraudulent requests for information. The firm blocked the email address after discovering the scam and alerted the relevant government agency, law enforcement, and regulators.

Revolut did not disclose the exact number of impacted individuals, which government agency was involved, or whether the incident was limited to a specific market. The spokesperson said only that a "limited" number of customers were impacted.

Well-known crypto security researcher ZachXBT posted about Revolut's notification email late on Friday, suggesting the incident appeared to have been targeted at high net worth users.

The breach comes as Revolut, which has more than 80 million customers globally and operates as a bank in more than 30 countries, reportedly weighs a potential public listing. Earlier this month the U.S. Office of the Comptroller of the Currency granted conditional approval for Revolut to set up a national bank in the country, which the firm expects to launch in the first half of 2027.

§

Analysis

Why This Matters

  • Customer impact: Affected individuals face heightened risk of identity theft and fraud, as attackers now possess government-issued identity documents, verification selfies, and financial records.
  • Trust and regulatory scrutiny: The breach, which exploited a government email domain, raises questions about the security of data-sharing protocols and could trigger investigations by financial regulators in multiple jurisdictions.
  • IPO timeline: Revolut is reportedly planning a public listing that could value it at up to $200 billion. The breach could complicate investor confidence and regulatory approvals.

Background

Revolut is a British fintech that has rapidly expanded from a digital banking app into a full-service financial platform with more than 80 million customers globally. It holds banking licenses in several European countries and recently secured conditional approval for a U.S. national bank charter. The company has been in talks for an initial public offering that could be one of the largest in fintech history. Data breaches involving the exploitation of trusted domains (like government email systems) are a known attack vector, often used to target high-value individuals.

Key Perspectives

Affected customers: Those whose passports, driver's licenses, and financial records were compromised now face potential identity theft and financial fraud. They expect transparency about the breach and proactive support from Revolut. Revolut: The company has moved quickly to block the fraudulent email address, notified affected customers, and alerted law enforcement and regulators. It maintains that its systems and customer funds were not compromised. Security researchers and critics: The lack of disclosure about the number of victims and the specific government agency involved raises concerns about accountability. The incident highlights that even legitimate government email domains can be spoofed or misused, requiring stronger verification processes for data requests.

What to Watch

  • Regulatory response: Whether data protection authorities in the UK, EU, or other markets launch formal investigations and impose fines.
  • Detailed disclosure: Revolut may be compelled to reveal the scale of the breach and the government agency exploited, especially if class-action lawsuits follow.
  • Impact on IPO plans: How potential investors and underwriters react to the breach in light of the company's stated $200 billion valuation target.

Sources

newspaper

Zotpaper

Articles published under the Zotpaper byline are synthesized from multiple source publications by our AI editor and reviewed by our editorial process. Each story combines reporting from credible outlets to give readers a balanced, comprehensive view.